Falhas do tipo CWE-120

3.165 resultados

Estouro de buffer clássico

A aplicação copia dados em um buffer sem validar o tamanho, permitindo que um atacante sobrescreva memória adjacente. Isso pode corromper variáveis, desviar o fluxo de execução ou injetar código malicioso que será executado com os mesmos privilégios da aplicação.

Exemplo

Um formulário web aceita um nome de usuário e o copia direto em um array de 32 bytes sem checar comprimento. Um atacante envia 200 bytes; o excesso sobrescreve o endereço de retorno da função, desviando a execução para código dele. Comum em CGI antigos, serviços network e binários C/C++ mal escritos.

Como mitigar

Use funções seguras (strncpy, strlcpy em vez de strcpy; snprintf em vez de sprintf) que respeitam limites. Sempre valide e sanitize entrada externa antes de copiar. Em C moderno, considere AddressSanitizer ou ferramentas estáticas para detectar cópias inseguras em tempo de compilação.

CVE-2025-45866MEDIUMTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interfaceEPSS 0.3%CVE-2025-4891MEDIUMcode-projects Police Station Management System Display Record source.cpp display buffer overflowEPSS 0.3%CVE-2025-4888MEDIUMcode-projects Pharmacy Management System Add Order Details take_order buffer overflowEPSS 0.3%CVE-2020-37202MEDIUMNetworkSleuth 3.0.0.0 - 'Key' Denial of ServiceEPSS 0.3%CVE-2024-44234MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS SeEPSS 0.3%CVE-2020-37203MEDIUMOffice Product Key Finder 1.5.4 - Denial of ServiceEPSS 0.3%CVE-2024-40427HIGHStack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the progrEPSS 0.3%CVE-2024-44233MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS SeEPSS 0.3%CVE-2024-44232MEDIUMThe issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS SeEPSS 0.3%CVE-2025-1365MEDIUMGNU elfutils eu-readelf readelf.c process_symtab buffer overflowEPSS 0.3%CVE-2023-25435MEDIUMlibtiff 4.5.0 is vulnerable to Buffer Overflow via extractContigSamplesShifted8bits() at /libtiff/tools/tiffcrop.c:3753.EPSS 0.3%CVE-2025-55297MEDIUMESF-IDF BluFi Example Memory Overflow VulnerabilityEPSS 0.3%CVE-2025-43370MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly large path value may craEPSS 0.3%CVE-2022-47091HIGHGPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow in gf_text_process_sub function of filters/load_text.cEPSS 0.3%CVE-2024-24972MEDIUMBuffer Copy without Checking Size of Input (CWE-120) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authoriseEPSS 0.3%CVE-2011-10025HIGHSubtitle Processor 7.7.1 .m3u SEH Unicode Buffer OverflowEPSS 0.3%CVE-2026-3081HIGHGStreamer H.266 Codec Parser Stack-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-28569HIGHBuffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::XEPSS 0.3%CVE-2021-34987HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.1 (49187). An attacker EPSS 0.3%CVE-2025-44560CRITICALowntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.EPSS 0.3%